CVE-2019-25679

Severity CVSS v4.0:
HIGH
Type:
CWE-787 Out-of-bounds Write
Publication date:
05/04/2026
Last modified:
20/04/2026

Description

RealTerm Serial Terminal 2.0.0.70 contains a structured exception handling (SEH) buffer overflow vulnerability in the Echo Port tab that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a buffer overflow payload with a POP POP RET gadget chain and shellcode that triggers code execution when pasted into the Port field and the Change button is clicked.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:crun:realterm:2.0.0.70:*:*:*:*:*:*:*